Data Storage Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Information for Data Storage Professionals
Brocade delivers
cloud-optimized networking solutions
to deploy, manage, and scale networks.

www.brocade.com
Wednesday, May 22nd 
Introducing Simpana® 10 software
Home
Data Centers
Storage Solutions
Storage Networks
Data Storage Issues
Data Security
Enterprise I.T.
DST Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement
Data Security

VMware Source Code Stolen, Posted Online

VMware Source Code Stolen, Posted Online
April 26, 2012 10:42AM

Bookmark and Share
"VMware proactively shares its source code and interfaces with other industry participants to enable the broad virtualization ecosystem today," said VMware's Iain Mulholland. "We take customer security seriously and have engaged internal and external resources, including our VMware Security Response Center, to...investigate."

CommVault is a data and information management software company dedicated to providing organizations worldwide with a radically better way to manage data and information. Their unique Solving Forward philosophy allows them to deliver complete solutions with infinite scalability and unprecedented control over data and costs. Be among the first to experience Simpana 10 software. Click here now.

An anonymous hacker is claiming credit for stealing more than 1 terabyte of confidential source code from VMware. A hacker by the name of Hardcore Charlie is taking credit for posting the code online.

VMware said its security team became aware of the public posting of a single file from the ESX source code, as well as the possibility that more files may be posted in the future, on Monday. The company revealed that the posted code and associated commentary dates to the 2003 to 2004 time frame.

Iain Mulholland, director of the VMware Security Response Center, was quick to say that just because source code may have been publicly shared does not necessarily mean that there is any increased risk to VMware customers.

"VMware proactively shares its source code and interfaces with other industry participants to enable the broad virtualization Relevant Products/Services ecosystem today," Mulholland wrote in a VMware blog post. "We take customer Relevant Products/Services security seriously and have engaged internal and external resources, including our VMware Security Response Center, to thoroughly investigate."

Virtual Infrastructure: A Prime Target

Mulholland said VMware will continue to provide updates to the VMware community if and when additional information is available. That was on Tuesday. VMware has not yet offered any new information.

We caught up with Eric Chiu, president of HyTrust, a cloud Relevant Products/Services and virtual Relevant Products/Services infrastructure Relevant Products/Services control company, to get his views on VMware's security issue. He started out by telling us that virtualization is mainstream, with more than 50 percent of enterprise Relevant Products/Services data Relevant Products/Services centers now virtualized.

"Because of this success, virtual infrastructure is a prime target for attack -- so the theft of VMware ESX source code, similar to RSA's breach last year, is no surprise," Chiu said. "Platform security for virtual infrastructure is a must -- without securing the virtual infrastructure, enterprises are leaving a huge area of their data center open to attack."

No One Is Immune

We also touched base with Mark Bower, data protection expert and vice president at Voltage Security, a data-centric security and simplified key management Relevant Products/Services firm. He told us that although the details are sketchy, the attack once again shows that even the best-prepared companies can have risks from consequential third-party access to data out of their control.

"The real pain for the industry in this case is less about counterfeit VMware instances, but the intimate knowledge attackers may now possess of possible vulnerabilities in a critical virtualization tool that is the foundation for many enterprise data centers, clouds and applications," Bower said.

"Nobody should be assuming that security by obscurity is the way to protect Relevant Products/Services critical data -- that's been the case since the 1800s. This incident again underpins the industry's critical and growing need to adopt a data-centric security approach -- so irrespective of where data may reside, even in vulnerable systems it stays protected until the moment it's needed. And in the attackers' hands, it's useless -- even if they know exactly how the container the data is in functions and can itself be compromised."

Tell Us What You Think
Comment:

Name:

Simon:

Posted: 2012-04-27 @ 7:21pm PT
Awesome. Hiding knowledge for profit is immoral: to keep people ignorant in order to exploit them is an evil, no matter how numb the world has become to it after its being done for so long. Stealing source code in order to open it up is no more deceptive, and in fact for all its illegality I think it's more socially responsible than hiding code for profit. So nice work, Hardcore Charlie.

Advertisement



 Data Security
1. Blue Coat Beefs Up Big Data Security
2. China Hackers Resume U.S. Attacks
3. Financial Times Latest Hacking Target
4. Hackers Find Smartphones Useful
5. Investors Funding Cyberwarfare


advertisement


 Most Popular Articles
1. Half of Companies To Mandate BYOD by 2017, Gartner Says
2. Best of Interop Award Winners Announced
3. Novell Filr Offers IT-Friendly Dropbox Alternative
4. BitTorrent Offers Alpha of P2P File-Syncing App
5. 75% of Breaches Financially Motivated, 20% Are Espionage

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Nvidia GPU Boosts Citrix XenDesktop
  Security Alert: New Trojan Attacking
  Blue Coat Beefs Up Big Data Security
  Backing Up Is Hard To Do, Yet Critical
  Dell Kills Its In-House Public Cloud

 Technology Marketplace

BYOD & MDM
Forrester Research Inc., Report: BYOD from AT&T. Make everyone more efficient.
 
Cloud & Virtualization
Brocade technologies help enable the full benefits of virtualization.
Riverbed Stingray Traffic Manager on Amazon Web Services
 
Contact Centers
Unlock the potential in your people with Microsoft Dynamics
 
Customer Service
Unlock the potential in your people with Microsoft Dynamics
 
Data Security
Simpana® 10 software: an exponential leap forward
 
Data Storage
Brocade makes it easier to deploy, manage, and scale networks.
 
Enterprise Software
Simpana® 10 software: an exponential leap forward
 
Network Security
Brocade makes it easier to deploy, manage, and scale networks.
 
Enterprise Hardware Spotlight

Dell Kills Its Public Cloud Effort, Will Offer Partner Marketplace
Putting the kibosh on its efforts to build out a public cloud, Dell has announced a new program to offer a choice of cloud Infrastructure-as-a-Service through a central marketplace of partners.

Dell's Dismal Quarter Shows PC Maker's Challenges
Dell's financial decay worsened during its latest quarter as the company slashed its personal computer prices in response to the growing popularity of smartphones and tablets in the beleaguered industry.

U.S. Defense Department Gives iOS 6 Security OK
In a vote of confidence for Apple's iOS devices, the Defense Department has given the all-clear for employees to use iPads and iPhones for work. But only those running iOS 6, and only if issued by the government.

Advertisement
Navigation
Data Storage Today
Home/Top News | Data Centers | Storage Solutions | Storage Networks | Data Storage Issues | Data Security | Enterprise I.T.
DST Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 Data Storage Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.